How to improve Web access controls
I need to control user access to different Web sites. For example, permit user1 to access www.yahoo.com after providing a username and password, but deny access for user2 (or require an admin password). In other words, I need software that stores different users' profiles and what they can and cannot access. What proxy server or firewall would give me such facility?

    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

To provide granular access to specific Internet sites for specific users, you need to augment your existing proxy server, or firewall, with a Web filtering appliance. While you can tune proxies and firewalls to block certain kinds of traffic and Web sites, they don't work as well for individual user profiles.

Web filtering products, such as Websense, Blue Coat and 8e6, operate as appliances meshed into your firewall system, but unlike firewalls, they are deployed to block specific content. You can tailor Web filters to your company's particular policies for employee Internet use. They can use white and black lists to control what users can and cannot access.

The obvious targets, like pornography and gambling sites, would most likely be on most companies' hit list for the deployment of Web filtering proxies. However, if your company has a policy against employees accessing personal email accounts on company time, these products can do the job.

Again, unlike firewall rules, which are based on traffic, these products can be adjusted to allow selective access to individual employees or groups of employees that may need special access for business reasons. Websense, for example, has a User Service software component that calls your directory service, whether Active Directory (AD) or LDAP, to filter users based on any size and type of organizational unit from domains down to individual users. Blue Coat and 8e6 both offer similar user authentication schemes in their products that work with AD and LDAP, as well.

Although these filtering products don't store profiles, they do work with the profiles in your existing authentication systems to allow or block individual and group access. That's why it's important to check how these products work with your directory services, before purchasing one.

For More Information

  • Visit our resource center and learn how to improve your enterprise Web access controls.
  • .

    This was first published in June 2006